Skip to content

CVE-2023-2309 | wpForo Forum

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability..This CVE has a CVSS3.1 score of 7.6 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-2309
CVE StatePUBLISHED
BaseScoreNA
BaseSeverityNA
VectorStringNA
VersionNA

References for CVE-2023-2309 :
https://wpscan.com/vulnerability/1b3f4558-ea41-4749-9aa2-d3971fc9ca0d

Metric TypeMetric Score
AttackVector(AV)NA
AttackComplexity(AC)NA
PrivilegesRequired(PR)NA
UserInteraction(UI)NA
Scope(S)NA
Confidentiality(C)NA
Availability(A)NA
Integrity(I)NA